FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security operations, incident response, and threat detection, with a strong focus on developing and tuning detection mechanisms across various environments. Proficient in creating AI workflows and utilizing automation to enhance investigation processes and improve security outcomes.
Highest-signal resume keywords
Security OperationsIncident ResponseDetection EngineeringSIEM, EDR, SOARPython Programming
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Threat DetectionDetection TuningAlert TriageInvestigation WorkflowsAI Workflow CreationDetection-as-Code PracticesCloud Platform ExperienceAutomation Platform UsageTelemetry AnalysisSecurity Judgment
Soft Skills
Clear DocumentationCollaborative CommunicationInclusive Teamwork
Tools & Technologies
SIEMEDRSOARGitHubCI/CDGoogle CloudAWSAzure
Industry Keywords
Threat IntelligenceSecurity FindingsSaaS SecurityIncident ContainmentProactive Threat Identification
Tech Stack
Tools & technologiesAWSAzureCloudPython
About the role
Key responsibilities & impact- Identify detection opportunities and define telemetry requirements
- Partner with the detection infrastructure squad and data owners to make detection and investigation signals available
- Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, email, and other security-relevant environments
- Investigate and prioritize alerts, determine security impact, and participate in incident containment and remediation
- Build repeatable investigation workflows and playbooks for alert triage, evidence collection, decision-making, escalation, containment, and response
- Improve proactive threat identification and threat hunting using internal telemetry and external threat intelligence
- Create AI workflows for Detection and Response that enrich alerts, analyze evidence, guide investigations, and automate repetitive response work
- Measure detection effectiveness, identify coverage gaps, and tune detections to balance security value, fidelity, and analyst workload
- Use SIEM, EDR, SOAR, and related security platforms to research threats, develop detections, investigate alerts, and validate security outcomes
- Share knowledge, document decisions, and communicate security findings to technical and non-technical audiences
- Partner with detection infrastructure and teams across Spotify to support detection and response at scale
Requirements
What you’ll need- 3+ years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work
- Understanding of analyst alert triage and investigation workflows
- Experience creating and tuning detections based on attacker behavior, available telemetry, and expected investigation paths
- Experience with SIEM, EDR, SOAR, or comparable monitoring and response technologies
- Ability to write code or use an automation platform to analyze security telemetry, enrich alerts, build investigation workflows, and remove repetitive work
- Experience with Python or a similar language is valuable
- Understanding of detection-as-code practices, including GitHub, peer review, CI/CD, testing, and safely managing production detection content
- Experience with at least one major cloud platform, such as Google Cloud, AWS, or Azure
- Understanding of common threats affecting SaaS-oriented corporate and production environments
- Ability to document clearly, collaborate inclusively, and explain security concepts to people with different backgrounds and expertise
- Ability to create and critically evaluate AI workflows for detection development, alert triage, security investigations, and response
- Appropriate security judgment and human oversight
Benefits
Comp & perks- Equity
- Health insurance
- Six-month paid parental leave
- 401(k) retirement plan
- Monthly meal allowance
- 23 paid days off
- Paid flexible holidays
- Paid sick leave
- Flexible work from home
- Reasonable accommodations during the interview process
